EXPOSURES › CVE-2023-46604
CVE-2023-46604
CRITICAL ⌖ ON CISA KEV · EXPLOITEDA remote attacker could execute arbitrary shell commands on an Apache ActiveMQ broker by exploiting a deserialization vulnerability in the OpenWire protocol.
This deserialization flaw allows remote code execution without requiring authentication, enabling attackers to pivot into networks hosting critical infrastructure. DIB organizations must ensure ActiveMQ is patched and network-isolated, as this vulnerability was actively exploited in the wild and linked to ransomware campaigns.
Shame score — A critical, actively exploited vulnerability in a widely deployed messaging broker that enables remote code execution and was linked to ransomware, representing a severe avoidable risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.